1# /etc/systemd/system/snowbound-relay.service: the Live Share relay behind a TLS proxy on
2# this machine (README.md). Options go on ExecStart, or as SNOWBOUND_RELAY_* in Environment.
3[Unit]
4Description=Snowbound Live Share relay
5After=network-online.target
6Wants=network-online.target
7
8[Service]
9ExecStart=/usr/local/bin/snowbound-relay --listen 127.0.0.1:23592 --trust-forwarded true
10Restart=always
11RestartSec=2
12DynamicUser=yes
13# Two threads a connection, and a few more.
14TasksMax=600
15LimitNOFILE=1024
16MemoryMax=512M
17NoNewPrivileges=yes
18ProtectSystem=strict
19ProtectHome=yes
20PrivateTmp=yes
21PrivateDevices=yes
22ProtectKernelTunables=yes
23ProtectKernelModules=yes
24ProtectControlGroups=yes
25RestrictAddressFamilies=AF_INET AF_INET6
26RestrictNamespaces=yes
27LockPersonality=yes
28MemoryDenyWriteExecute=yes
29SystemCallArchitectures=native
30CapabilityBoundingSet=
31
32[Install]
33WantedBy=multi-user.target